Patents Assigned to CROWDSTRIKE, INC.
  • Patent number: 12712890
    Abstract: A cybersecurity event validation service provides a user-friendly scheme for detecting a cyberattack or threat. The cybersecurity event validation service accepts very simple, high-level, user-friendly descriptions of the cyberattack or threat. A user of the cybersecurity event validation service thus need not input detailed hardware/software events that specify the potential cyberattack or threat. The cybersecurity event validation service, instead, validates the user's very simple descriptions for correctness. If the user's very simple descriptions conform to basic rules or requirements, then the cybersecurity event validation service elegantly fills in the deep hardware and software details using context and inferences. The cybersecurity event validation service thus elaborates and enhances the user's very simple descriptions by supplying specific hardware/software details needed to detect the cyberattack or threat.
    Type: Grant
    Filed: November 1, 2023
    Date of Patent: August 18, 2026
    Assignee: CrowdStrike, Inc.
    Inventor: Providence Salumu
  • Patent number: 12705364
    Abstract: Prediction of matches between CPEs and banners greatly improves computer functioning. Many web services have an unknown common platform enumeration (CPE). When the CPE is unknown, a computer system is unable to obtain cybersecurity flaws and software fixes for a software product or web service. A similarity between the CPE and a service banner, though, accurately predicts a match the CPE and the web service. CPEs, for example, may thus be identified for old, obsolete, and uncomment software products and services.
    Type: Grant
    Filed: September 25, 2024
    Date of Patent: August 11, 2026
    Assignee: CrowdStrike, Inc.
    Inventors: Shaefer Drew, Moshe Shimon Perez, Michael Avraham Brautbar, Yotam Lichter
  • Patent number: 12705223
    Abstract: A value is assigned to a rate threshold for adding child nodes to a distinct parent node in a tree data structure. A first datum comprising a first variable assigned a first value and a second variable assigned a first value is added to the tree at a first timestamp, by adding to the first level in the tree a first parent node representing the first variable assigned the first value and adding to the second level in the tree a first child node representing the second variable assigned the first value and connected by a first directed edge from the first parent node. A second datum comprising the first variable assigned the first value and the second variable assigned a second value is received at a second timestamp. The method blocks adding to the second level in the tree a second child node representing the second variable assigned the second value and connected by a second directed edge from the first parent node when a rate based on the first timestamp and the second timestamp exceeds the rate threshold.
    Type: Grant
    Filed: September 2, 2022
    Date of Patent: August 11, 2026
    Assignee: Crowdstrike, Inc.
    Inventors: Daniel W. Brown, Johnathan Hoyt, Sseziwa A. Mukasa, Thomas R. Hobson
  • Patent number: 12699778
    Abstract: Techniques for using supervised machine learning to train risk models used to analyze group data for security risks are discussed herein. A system can receive a user input identifying risk values associated with categories or attributes of a group having access to computing resources. The system can use the risk model to generate a risk score for the group. The risk score can be used to further analyze aspects of the group or provide recommendations to reduce or eliminate security risks.
    Type: Grant
    Filed: November 21, 2023
    Date of Patent: August 4, 2026
    Assignee: CrowdStrike, Inc.
    Inventors: Christopher Balles, Kellen Arb, Michael Cosmadelis, Sean Corlin, Jeremy Fintel
  • Patent number: 12694108
    Abstract: Deception-based techniques for responding to security attacks are described herein. The techniques include transitioning a security attack to a monitored computing device posing as a computing device impacted by the security attack and enabling the adversary to obtain deceptive information from the monitored computing device. Also, the adversary may obtain a document configured to report identifying information of an entity opening the document, thereby identifying the adversary associated with the attack. Further, the techniques include determining that a domain specified in a domain name request is associated with malicious activity and responding to the request with a network address of a monitored computing device to cause the requesting process to communicate with the monitored computing device in place of an adversary server. Additionally, a service may monitor dormant domains names associated with malicious activity and, in response to a change, respond with an alert or a configuration update.
    Type: Grant
    Filed: October 3, 2023
    Date of Patent: July 28, 2026
    Assignee: CrowdStrike, Inc.
    Inventors: Adam S. Meyers, David F. Diehl, Dmitri Alperovitch, George Robert Kurtz, Sven Krasser
  • Patent number: 12694146
    Abstract: Multi-modal query processing greatly improves computer functioning. A single cybersecurity sensory nodal server concurrently processes standing queries, agent point queries, and agent fleet queries. The single cybersecurity sensory nodal server is dedicated to locally storing electronic data associated with a cybersecurity sensory agent installed at a client device. Because the single cybersecurity sensory nodal server locally stores the single source of the electronic data, the single cybersecurity sensory nodal server answers the standing queries, agent point queries, and agent fleet queries using less hardware resources, less network resources, less electrical energy, and less time.
    Type: Grant
    Filed: October 9, 2024
    Date of Patent: July 28, 2026
    Assignee: CrowdStrike, Inc.
    Inventors: Timothy Jason Berger, Marcus Andrew King, Thomas Francis Lyons, Brent Ryan Nash, James Robert Plush
  • Patent number: 12689642
    Abstract: A system and method of using generative AI to identify exposures of computing devices on computing networks to actual and/or potential threats. The method includes collecting a plurality of responses from a plurality of devices to a target device on a private network. The method includes providing the plurality of responses to a classification model trained to assign device descriptions for device responses based on semantic matching of the device responses to database data. The method includes assigning, by the processing device using the classification model, a plurality of device descriptions for the plurality of responses to the target device, each response is respectively associated with one or more device descriptions of the plurality of device descriptions. The method includes generating, based on the plurality of device descriptions, a status report comprising a list of network addresses associated with a group of devices having access to the target device.
    Type: Grant
    Filed: November 29, 2023
    Date of Patent: July 21, 2026
    Assignee: CrowdStrike, Inc.
    Inventors: Paul Sumedrea, Damian Monea
  • Patent number: 12688281
    Abstract: The present disclosure provides techniques for AI model-based detection explainability. A processing device obtains computer-readable text and an indication of a false positive detection of malicious behavior with respect to the computer-readable text by a cybersecurity system, The processing device obtains, via an artificial intelligence (AI) model trained to generate language, a reason for the false positive detection of the malicious behavior. The processing device provides an indication of the reason for the false positive detection to a destination device.
    Type: Grant
    Filed: May 30, 2024
    Date of Patent: July 21, 2026
    Assignee: CrowdStrike, Inc.
    Inventors: Diana Bolocan, Mihaela-Petruta Gaman
  • Publication number: 20260205476
    Abstract: IT asset discovery services and external attack surface management (or EASM) services identify computers, servers, smartphones, and other devices that are exposed to the public Internet. Any device that can connect to the public Internet may be vulnerable to cybersecurity attacks. The services identify a device exposed to the public Internet by generating an asset inventory discovery graph. Graphical nodes describe asset inventory investigative records, and edges between the graphical nodes describe asset inventory investigative methods. The nodes thus capture asset investigatory details (such as website URL, IP addresses, and HTML content), and the edges capture how the asset investigatory details were discovered (such as Internet searches, DNS records, and WHOIS records). The services use the asset inventory discovery graph to identify an entity's Internet-facing assets.
    Type: Application
    Filed: January 13, 2025
    Publication date: July 16, 2026
    Applicant: CrowdStrike, Inc.
    Inventors: Michael Brian Goldgeier, Yaron Tal, Moshe Shimon Perez, Michael Glyer, Yotam Lichter
  • Patent number: 12682057
    Abstract: A cloud-based file integrity monitoring service identifies content changes to a computer file. An endpoint cybersecurity agent monitors its host client device for read/write and other operating system events associated with the computer file. When the endpoint cybersecurity agent detects each operating system event, the endpoint cybersecurity agent captures and reports, in real time or near real time, a snapshot of the file content representing the computer file. So, as the host client device changes the computer file with each operating system event, the endpoint cybersecurity agent uploads timestamped snapshots of the file content to a cloud-based file integrity monitoring service. The cloud-based file integrity monitoring service stores each snapshot of the file content, thus logging a change history for the computer file.
    Type: Grant
    Filed: May 30, 2024
    Date of Patent: July 14, 2026
    Assignee: CrowdStrike, Inc.
    Inventors: Silviu-Alexandru Badragan, Andrei-Viorel Cotiga, Adam Freund, Samantha Alyn Goresh, Ioan Tinca
  • Patent number: 12676833
    Abstract: A firewall receives a flow of data from a first computing resource destined to a second computing resource and searches, in a memory, a prefix tree data structure, the prefix data structure comprising a linked plurality of nodes corresponding to normalized criteria for each of a plurality of rules, for any rule in the plurality of rules that applies to controlling the received flow of data between the first computing resource and the second computing resource. If the search is successful, a set of rules in the prefix tree data structure is identified that apply to controlling the received flow of data from the first computing resource to the second computing resource in response to the searching. One of those rules in the set is then selected to control the received flow of data from the first computing resource to the second computing resource.
    Type: Grant
    Filed: January 28, 2022
    Date of Patent: July 7, 2026
    Assignee: Crowdstrike, Inc.
    Inventors: Keehun Nam, Tim Adams
  • Patent number: 12675570
    Abstract: Methods and systems implement computing systems configured to trigger a volatile memory scan based on execution of computer-executable instructions, and to downselect scope of a volatile memory scan. Such techniques for triggering scans are sufficiently selective to avoid volatile memory scans for each and every running process, or vast majority of running processes. Moreover, volatile memory scans are triggered responsively after the computer-executable instructions are run, so that target processes to be scanned have not yet terminated at the time of the volatile memory scan. Additionally, a variety of techniques are implemented to minimize the volatile memory scans adversely impacting computational performance of the computing system.
    Type: Grant
    Filed: August 11, 2023
    Date of Patent: July 7, 2026
    Assignee: CrowdStrike, Inc.
    Inventors: Jennifer Mankin, Blair Foster, Marc Leclair, Eric Kuhl
  • Publication number: 20260178829
    Abstract: An LLM log parsing service parses log data using at least one large language model. The LLM log parsing service, however, may evaluate multiple log parser candidates. Each log parser candidate parses a sample of the log data using the at least one large language model. The LLM log parsing service generates a log parser decision that selects which one of the log parser candidates best performs as a log parser. The LLM log parsing service then parses the log data using the best log parser.
    Type: Application
    Filed: December 20, 2024
    Publication date: June 25, 2026
    Applicant: CrowdStrike, Inc.
    Inventors: James Robert Plush, Sean Berry
  • Patent number: 12665921
    Abstract: Techniques for calculating risk scores of entity assignments are discussed herein. The system generates a probability matrix using a collaborative filtering technique such as singular value decomposition. The probability matrix is populated with probability values for each entity representing a probability that, based on the various relationships or associations of that entity with other entities, the entity has been granted an assignment. Risk values are used to provide a weighting value to assignments, separating relatively higher risk assignments from relatively lower risk assignments. The system thereafter calculates a risk score for one or more of the entities using the information in the assignment matrix, the probability matrix, and the risk values. The system can flag or identity one or more entities whose risk scores do not meet various criteria.
    Type: Grant
    Filed: November 28, 2023
    Date of Patent: June 23, 2026
    Assignee: CrowdStrike, Inc.
    Inventors: Robert Molony, Michael Brautbar, Manu Nandan, Ciaran O'Brien
  • Publication number: 20260170133
    Abstract: A cybersecurity model assessment service assesses machine learning and/or artificial intelligence models for cybersecurity threats. The cybersecurity model assessment service may particularly assess a pickle file associated with an AI/ML model. A dynamic emulation reveals whether the pickle file represents normal or abnormal computer behavior. The dynamic emulation of the pickle file may thus reveal whether the AI/ML model is safe or unsafe to use.
    Type: Application
    Filed: December 16, 2024
    Publication date: June 18, 2026
    Applicant: CrowdStrike, Inc.
    Inventors: Stefan Cicos, Alexandru-Constantin Ghita, Andrei Stoian, Paul-Danut Urian
  • Publication number: 20260172451
    Abstract: An endpoint cybersecurity reinforcement learning agent uses reinforcement learning to implement cybersecurity actions. The endpoint cybersecurity RL agent interfaces with a host operating system as an antimalware driver. The endpoint cybersecurity RL agent receives an event notification generated by the OS and determines a responsive cybersecurity action using the reinforcement learning. The endpoint cybersecurity RL agent implements the cybersecurity action via the OS. The endpoint cybersecurity RL agent thus greatly improves computer functioning by quickly learning to identify new/novel suspicious events and operations.
    Type: Application
    Filed: December 16, 2024
    Publication date: June 18, 2026
    Applicant: CrowdStrike, Inc.
    Inventors: Arnd Korn, Ian Torres
  • Patent number: 12659228
    Abstract: A system and method of using generative AI to recommend and validate asset and/or cloud configurations. The method includes acquiring a set of parameters associated with one or more network entities of a computing network. The method includes providing the set of parameters to a configuration model trained to generate, based on semantic matching, recommended configurations for network entities and validated configurations for the network entities. The method includes generating, by a processing device using the configuration model, one or more recommended configurations for the one or more network entities based on the set of parameters.
    Type: Grant
    Filed: January 5, 2024
    Date of Patent: June 16, 2026
    Assignee: CrowdStrike, Inc.
    Inventors: Paul Sumedrea, Damian Monea
  • Patent number: 12651057
    Abstract: A deterministic finite automata (DFA) is used by an extended Berkley packet filter (or “eBPF”) to monitor file system operations and non-file system operations. The DFA is stored as an eBPF map. Before a kernel of an operating system executes any file system operation, the kernel runs an eBPF program that queries the DFA for a filename associated with the system operation. The DFA represents safe/suspicious filenames associated with computer files. If the filename matches the DFA, then the kernel notifies a cybersecurity agent. The cybersecurity agent may then block or allow the file system operation, depending on whether the filename is safe or suspicious. The DFA stored in the extended BPF thus greatly improves computer functioning by very quickly and simply identifying safe/suspicious operations.
    Type: Grant
    Filed: October 26, 2023
    Date of Patent: June 9, 2026
    Assignee: CrowdStrike, Inc.
    Inventor: Justin John Kevin Deschamp
  • Patent number: 12645796
    Abstract: The present disclosure provides an approach of analyzing multiple modalities of a file to produce multiple analysis tokens. Each one of the analysis tokens corresponds to a respective modality of the file. The approach provides the multiple analysis tokens to an artificial intelligence model, which is trained to produce an intermediate representation vector based on the plurality of analysis tokens. In turn the approach uses the artificial intelligence model to produce, based on the intermediate representation vector, a classification that indicates whether the file corresponds to a cybersecurity threat.
    Type: Grant
    Filed: January 25, 2024
    Date of Patent: June 2, 2026
    Assignee: CrowdStrike, Inc.
    Inventors: Andrew Southgate, Paul Sumedrea
  • Patent number: 12632624
    Abstract: The present disclosure provides techniques for sensor event based activity hour modelling. A processing device obtains, via a sensor application installed on a user device, a plurality of events occurring on the user device, where each event in the plurality of events includes a respective day and a respective time. The processing device aggregates, based on the respective day and the respective time, the plurality of events to generate time series data. The processing device performs a smoothing operation on the time series data to generate a curve. The processing device classifies an event on the user device as usual or unusual based on a baseline level of activity on the user device and the curve.
    Type: Grant
    Filed: January 21, 2025
    Date of Patent: May 19, 2026
    Assignee: CrowdStrike, Inc.
    Inventors: Tim Rütermann-Franz, Cullen Boldt, Ori Zuckerman